Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 188 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 188

Single answerGoogle Cloud Platform

You are designing the perimeter security for an organization's Google Cloud environment. The organization requires that only specific IP ranges from trusted networks are allowed to access a public-facing application hosted on Compute Engine instances. Additionally, they want to ensure that no other traffic can reach these instances. What is the most appropriate configuration to meet these requirements?

  1. A

    Use VPC firewall rules to allow traffic only from the trusted IP ranges and deny all other traffic.

  2. B

    Use Cloud Armor to enforce IP-based access control and block all other traffic.

  3. C

    Use Identity-Aware Proxy (IAP) to restrict access to the application for specific users.

  4. D

    Use a combination of VPC Service Controls and IAM policies to restrict access to the application.

Show answer and explanation

Correct answer: A

Explanation

To secure a perimeter and restrict access to a public-facing application based on IP ranges, VPC firewall rules are the most appropriate solution. They allow you to define both allow and deny rules at the network level, ensuring only traffic from trusted IP ranges is permitted. Other options, such as Cloud Armor or IAP, focus on application-layer security or user authentication and are not the best fit for this requirement.

  • A. Correct.

    This is the correct configuration. VPC firewall rules are designed to control ingress and egress traffic at the network level, making them suitable for implementing IP-based access control and denying other traffic.

  • B. Incorrect.

    Cloud Armor is used for protecting applications against DDoS and application-layer attacks, but it is not the best choice for restricting access from specific IP ranges.

  • C. Incorrect.

    Identity-Aware Proxy (IAP) is used for user-based access control to applications, not for network-level IP restrictions.

  • D. Incorrect.

    VPC Service Controls and IAM policies are used to secure access to Google Cloud resources and APIs but are not suitable for implementing IP-based network perimeter security.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam